CiscoWorks Common Services Framework Help Servlet Cross Site Scripting Vulnerability
BID:47902
Info
CiscoWorks Common Services Framework Help Servlet Cross Site Scripting Vulnerability
| Bugtraq ID: | 47902 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-0961 CVE-2011-0961 |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2011 12:00AM |
| Updated: | Mar 19 2015 07:35AM |
| Credit: | Sense of Security Labs |
| Vulnerable: |
Cisco CiscoWorks Common Services 3.1.1 Cisco CiscoWorks Common Services 3.0.6 Cisco CiscoWorks Common Services 3.0.5 Cisco CiscoWorks Common Services 3.0.4 Cisco CiscoWorks Common Services 3.0.3 Cisco CiscoWorks Common Services 3.3 Cisco CiscoWorks Common Services 3.2 Cisco CiscoWorks Common Services 3.1 Cisco CiscoWorks Common Services 3.0 Cisco CiscoWorks Common Services 2.3 Cisco CiscoWorks Common Services 2.2 Cisco CiscoWorks Common Services 1.0 |
| Not Vulnerable: | |
Discussion
CiscoWorks Common Services Framework Help Servlet Cross Site Scripting Vulnerability
CiscoWorks Common Services is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this vulnerability could allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and launch other attacks.
This issue is being monitored by Cisco Bug ID CSCto12704.
CiscoWorks Common Services 3.3 and prior are vulnerable.
CiscoWorks Common Services is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.
Exploiting this vulnerability could allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and launch other attacks.
This issue is being monitored by Cisco Bug ID CSCto12704.
CiscoWorks Common Services 3.3 and prior are vulnerable.
Exploit / POC
CiscoWorks Common Services Framework Help Servlet Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URI is available:
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URI is available:
Solution / Fix
CiscoWorks Common Services Framework Help Servlet Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
CiscoWorks Common Services Framework Help Servlet Cross Site Scripting Vulnerability
References:
References: